# scripts/iso/answer.toml.tmpl — Proxmox auto-install answer template for the Felhom ISO pipeline. # # build-felhom-iso.sh renders this into a concrete answer.toml by substituting: # __FQDN__ <- profile's FELHOM_FQDN # __ROOT_HASH__ <- a FRESH THROWAWAY crypt hash minted per build (never a real credential) # __DISK_SETUP__ <- profile's FELHOM_DISK_SETUP block (disk-list OR a udev filter) # The rendered answer is then run through validate-answer with the OUTPUT-PARSE gate (validate-answer # returns exit 0 even on failure — spike S1 trap; the build parses the message text, never $?). # # This committed template carries ONLY the __ROOT_HASH__ placeholder, never a real hash. [global] keyboard = "en-us" country = "hu" fqdn = "__FQDN__" mailto = "noreply@felhom.eu" timezone = "Europe/Budapest" # THROWAWAY-PLACEHOLDER — build-felhom-iso.sh mints a fresh per-build crypt hash here. root-password-hashed = "__ROOT_HASH__" # Optional emergency/validation root SSH key (profile FELHOM_ROOT_SSH_KEY); blank -> line removed. __ROOT_SSH_KEYS__ [network] source = "from-dhcp" # Enable the baked first-boot stub (prepare-iso --on-first-boot). from-iso = no network / no # cert-rotation risk (R-21 ruling); fully-up = the stub runs after pveproxy so pvesh/pct work and # the retry unit it installs can drive host-install (spike S3/S8a). [first-boot] source = "from-iso" ordering = "fully-up" # --- disk selection (from the build profile) --- __DISK_SETUP__